SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

The Order of IT Security Measures Small Businesses Should 'Do First'

What you lack is not a sense of crisis, but the 'order'

The more you research what you 'should do' for security, the more it grows.
EDR, Zero Trust, targeted email training—.
If you consult with vendors, the quotes will be in the millions of yen. With insufficient budget and staff, only anxiety piles up.

If that is the case, what you lack is not a sense of crisis.The 'order' of what to tackle first for your company's size is what is missing. You simply don't have anyone in-house to teach you that.

If you get the order wrong, you lose twice

There are two losses when you get the order wrong.
One is that even after introducing expensive products, youremain with basic holes left open.
Accounts of former employees remaining, multi-factor authentication not being effective for everyone—actual intrusions start from these mundane entry points.
It is like having a high-end lock on the window while the front door is wide open.

The other is thatyou cannot get approval if you cannot explain the rationale for the order.
Budget will not be granted based on 'just feeling anxious'.
The order that allows you to say, 'I have filled the basic gaps that can be done for free. Next is this,' is what becomes the material for persuasion.

Before spending money, please check these three things

All of these can be checked and started withzero additional cost.

  1. Can you list the status of multi-factor authentication (MFA) for all accounts?—Can you immediately answer what percentage is set up? This is a prime example of a measure with zero cost and the greatest effect.

  2. Can you name everyone who has administrator privileges?—Just by narrowing down the number of people with strong privileges, you reduce risk. This is also zero yen.

  3. Do you have a track record of 'successfully restoring' from a backup?—It is not about whether you are taking backups, butwhether you have performed a restoration test. A backup that cannot be restored is the same as having none at all.

Only after these three are filled does it become worth considering tools.

Conclusion

For those who are a one-person IT department or have concurrent IT responsibilities, I have compiled a checklist of the key points for prioritizing security measures with limited budget and time.
I will let you know when it is published, so please follow me if you are interested.

いいなと思ったら応援しよう!